Find hidden security issues in code and containers before deployment
This tool automatically detects vulnerabilities and configuration errors hidden in container images or code repositories right before deployment. Trivy performs broad checks on operating system packages, software dependencies, infrastructure code, and sensitive information. It allows you to handle security checks with a single command, from the development environment to the deployment pipeline.
Inspection targets and items
Trivy inspects container images, file systems, Git repositories, virtual machine images, and Kubernetes clusters. Within these targets, it identifies OS packages and software dependency lists (SBOM), known vulnerabilities (CVE), infrastructure code (IaC) issues and configuration errors, sensitive information and secrets, and software licenses. It supports most popular programming languages, operating systems, and platforms.
Usage and installation
Trivy can be installed through various channels, including Homebrew, Docker, and binary downloads. The basic usage format is trivy <target> [--scanners <scanner1,scanner2>] <subject>. For example, you can check image vulnerabilities with trivy image python:3.4-alpine, or inspect file system vulnerabilities, secrets, and configuration errors with trivy fs --scanners vuln,secret,misconfig myproject/. It integrates with multiple platforms, such as GitHub Actions, Kubernetes operator, and VS Code plugins.
Canary builds and precautions
A Canary build is generated every time a push is made to the main branch. These builds are provided as Docker Hub, GitHub, and ECR images, as well as binaries, but they may contain critical bugs, so their use in production environments is not recommended. For stable usage, it is advisable to use the official release version.
Suitable targets and verification items
This tool is suitable for teams building DevSecOps workflows or automating security checks in container and cloud environments. Before use, verify the scope of supported scanners and targets, and ensure you are using a stable version rather than a Canary build. Trivy is an open-source project by Aqua Security; if you require more features, you can consider the commercial product Aqua.